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Abstract 

In the Russian cards problem, Alice, Bob and Catli draw a, b and c 
cards, respectively, from a publicly known deck. Alice and Bob must then 
communicate their cards to each other without Cath learning who holds 
a single card. Solutions in the literature provide weak security, where 
Alice and Bob’s exchanges do not allow Cath to know with certainty 
who holds each card that is not hers, or perfect security, where Cath 
learns no probabilistic information about who holds any given card. We 
propose an intermediate notion, which we call e-strong security, where the 
probabilities perceived by Cath may only change by a factor of e. We then 
show that a mild variant of the so-called geometric strategy gives e-strong 
safety for arbitrarily small e and appropriately chosen values of a,b, c. 


1 Introduction 

Consider the following problem, which appeared in the 2000 Moscow Mathe¬ 
matics Olympiad: 

Alice, Bob and Cath draw three, three and one cards, respectively, 
from a publicly known deck of seven. Alice and Bob wish to inform 
each other of the cards they hold, but they may only do so by public, 
unencrypted announcements. Moreover, they do not wish for Cath 
to know who holds a single card that is not hers. Can Alice and Bob 
achieve this? 

* estebanlan@gmail.com 
fdavid.fernandez@itam.mx 
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It later came to be known as the Russian cards problem na, and is interesting 
from a cryptographical viewpoint since it provides a framework for uncondi¬ 
tionally secure communication, perhaps the strongest notion of security that 
one may demand from a cryptographic protocol. 

1.1 Notions of cryptographic security 

Claude Shannon, one of the first people to formalize the study of cryptography, 
proposed several notions of cryptographic security. To be precise, he defined the 
following: 

• Computational Security: We say that a protocol is computationally 
secure for n if at least n operations are needed to break it. It is usually 
very difficult to prove that protocol is secure in this sense, as we would 
need to know all the possible strategies for attack. However, it is a good 
measure of when a system isn't secure, that is, when it fails to be secure 
for a relatively small n. 

• Provable Security: We say that a protocol is provably secure if we 
can link it with a ‘hard’ problem, cryptographic or not, in such a way that 
solving the second problem will allow us to break the encryption. In that 
case, we know that we need at least as many operations to break the code 
as we need to solve the second problem. Typically, the ‘hard’ problem is 
in NP but believed to not be in P. Many of the cryptographic protocols in 
use today are based on this notion of security. 

• Unconditional Security: A protocol is unconditionally secure if it 

can’t be broken even with unlimited computational resources; the eaves¬ 
dropper simply does not have enough information to reconstruct the orig¬ 
inal message. 

It should be clear that unconditional security implies both computational and 
provable security, and as such it would ideally be desirable to develop uncon¬ 
ditionally secure cryptographic protocols. However, such protocols tend to be 
unpractical and as such few of them are known, with a notable example being 
Vernam’s one time pad m- However, the setup of the Russian cards, which 
presupposes a secure dealing phase, provides a convenient setup for developing 
unconditionally secure protocols. 

1.2 Related work 

The Russian cards problem may be traced back to Kirkman [8], but recently 
it has received renewed attention after its inclusion in the 2000 Mathematics 
Olympiad [T3j. One of the solutions for deals of distribution type (3, 3,1) uses 
the Fano plane, a special case of a combinatorial design, which can also be used 
for many other distribution types [T] . Another solution uses modular arithmetic, 
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which can also be generalized for many distribution types where the eavesdrop¬ 
per holds one card [3]. These solutions use only two announcements, but some 
cases are known to require more. A solution using three announcements for 
(4,4, 2) is reported in [14] . and a four-step protocol for c = 0(a 2 ) and b = 0(c 2 ) 
is presented in [4]. The solution we will work with in this paper is similar to 
the one reported in [2], which also takes two steps. The Russian cards problem 
has also been generalized to a larger number of agents in urn- 

However, while the protocols mentioned above provide unconditionally se¬ 
cure solutions to the Russian cards problem in that the eavesdropper may not 
know with certainty who holds a given card, that does not mean that she may 
not have a high probability of guessing this information correctly. To this end, 
stronger notions of security are studied in [12]. There, a distinction is made 
between weak and perfect security; in perfectly secure solutions, Cath does not 
acquire any probabilistic information about the ownership of any specific card. 
All of the above solutions provide weak security in this sense, but Swanson 
and Stinson show how designs may be used to achieve perfect security, an idea 
further developed in m- 

The solutions we present here will provide an intermediate level of security 
between weak and perfect, controlling the amount of probabilistic information 
that may be acquired by the eavesdropper, while having the advantage of being 
much easier to construct than perfectly secure solutions. 


2 A Worked Example 

We will motivate the work in this article with a relatively small example. Let’s 
suppose we have 49 cards, with Alice holding 7, Cath holding 5 and Bob the 
rest. In this case, Alice can take advantage of the fact that there is a field F 7 
with 7 elements (the quotient Z/(7) forms a field), and thus may identify each 
point in the two-dimensional vector space over F 7 , which we will denote F 7 , 
with a card. Moreover, she can do this in such a way that her cards (marked 
by 4k) form a line. Suppose then that Cath holds the cards marked by £, while 
Bob holds the rest of the cards (<0). 

Alice then announces how she has distributed the cards on the plane. In 
this particular announcement, Cath’s cards all fall within the same line. This is 
an extreme case, but it is a real possibility, as Alice has no knowledge of Cath’s 
hand when she makes her announcement. Bob and Cath know that Alice’s hand 
falls on a line, but they do not know which line. Bob then knows exactly which 
cards Alice holds (since there is only one complete line that he does not hold), 
but Cath does not. However, she may consider it more likely that Alice holds 
one card over another. To illustrate this, let us consider the points labeled x 
and y in Figure El 

First we will take a look at x. Cath knows that, in order for Alice to hold 
x, one of the lines that passes through x must be Alice’s hand. We draw these 
lines on the plane. 

Cath knows that not all the lines that pass through x can be Alice’s hand, 
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Figure 1: Alice assigns each card to a point on the plane in such a way that her 
hand forms a line. She does not know how the other cards will fall, since she 
can only see her own hand. In this example, all of Cathy’s cards happen to fall 
on another line. 


because if a line contains a card that belongs to Cath, it clearly cannot be held 
in its entirety by Alice . In this case, only one line fits that description, so Cath 
takes it out of consideration. We denote this by drawing the line dotted. Every 
point in the plane has 8 lines that cross it; therefore, the point x still belongs 
to 7 hands that could possibly belong to Alice. 

However, this is not the case for all cards that Cath does not hold. Let us 
now turn our attention to y. While x was colinear with Cath’s hand, all the 
lines that contain y and one of Cath’s cards are different. In this case Cath 
can discard more lines than she could when considering x. Only 3 possible lines 
remain, compared to the 7 lines that pass through x and avoid Cath’s hand. 
Therefore, it seems to Cath that the point x would be more likely to belong to 
Alice’s hand than the point y as there are more possible hands that contain it. 
Before the announcement, both cards had the same probability to be in Alice’s 
hand but after the announcement, x seems far more likely. 

Note that the total number on lines in the announcement is 56. We also know 
that 36 of these lines contain a card that Cath holds. This is because there are 8 
lines touching each point, but the 5 points all share one line. Therefore Alice’s 
hand is one of the 20 lines that avoid Cath’s hand. Of those 20 only three 
contain y compared to the 7 that contain x. Thus, it seems to Cath that there 
is a 7 /20 = 0.35 probability that Alice holds x compared to 3 /20 = 0.15 that she 
holds y. Thus, according to the information that Cath has, it is more than twice 
as likely that Alice holds x as it is that she holds y. 

In this case, we know neither of the cards actually belongs to Alice, but we 
want to be able to quantify this information and control it, especially in higher 
dimensions where it is not as simple to visualize. Our goal is to show that, by 
choosing different parameters appropriately, we can make the different proba¬ 
bilities be arbitrarily close to each other. But first we need some preliminaries 
to make this precise. 
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Figure 2: Lines that Cath may discard from Alice’s announcement. It is impor¬ 
tant to note that most of the lines are truncated, as the natural representation 
of Fy is as a torus and lines are harder to visualize in two dimensions. 


3 Strategies and Probabilistic Security 

In this section we will set up the basic concepts needed to formalize the Russian 
cards problem and different notions of security that one may require from its 
possible solutions. We will assume that Alice holds a cards, Bob b and Cath c, 
and Q is the set of cards with |fl| = a + b + c. A deal (of size (a, b, c)) is a 
partition (A, B , C) of Q such that |A| = a, \B\ = b and \C\ = c; each of A, B , C 
represent the hand of Alice, Bob and Cath, respectively. 

3.1 Equitable strategies 

In most solutions to the Russian cards problem, Alice makes an announcement, 
after which Bob knows the entire deal and thus can make a second (trivial) 
announcement where he tells Alice which cards Cath holds. Thus we need only 
model Alice’s first announcement, and we follow [ 12] in referring to the way that 
Alice is to choose her announcement as a strategy. 

Suppose that Alice holds a cards, Bob holds b and Cath holds c. Given a 
set X and a natural number n, we denote by ('^) the set of n-element subsets 
of A, and we will refer to such sets as n-sets. We denote the cardinality of X 
by |A|. A possible hand for Alice is then an element of (^). In Alice’s first 
announcement she gives a set of possible hands that she may hold, and thus we 
may consider an announcement simply as a set A C ( s ^) . 

However, there are many possible announcements that may inform Bob of 
Alice’s hand, and it may be convenient for Alice to randomize from all such 
possible announcements. Thus a strategy for Alice consists on a probability 
distribution among the possible announcements that she may choose from. 

Definition 1. A strategy (on ( s a 2 )) is a function 6 that assigns to each hand 
A £ (^) a probability distribution over 2(“). We denote the probability of an 
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announcement A given the hand A as Pq(A\A). 

Given a strategy © and a hand A, we will say that A is a possible announce¬ 
ment if Pq(A\A) > 0. The set of possible announcements will be denoted by 
&A- 

When it is clear from context, we will drop the subindex © and write simply 
P(A\A) to simplify notation. It will also be convenient for computations if 
the number of possible announcements is independent of Alice’s hand. If we 
could guarantee that there are m possible announcements for each hand, we 
could always assign a probability of l /m to each individual announcement. If a 
strategy has this property, we will say it is equitable 1111- 

Definition 2. A strategy © is equitable if there exists a positive integer m such 
that, for every a-set A, |©a| = m and the probability of choosing a particular 
announcement A G &a is P(A\A) = 1/m. 

One advantage of equitable strategies is that we need less information to 
specify them than more general strategies. In particular, we may model equi¬ 
table strategies merely as a function 

where &a is the set of announcements with positive probability (and thus with 
probability 1 /m). Since the geometric strategy, which will be our main focus, is 
equitable, we will adopt this presentation. 

The first condition that a two-step solution to the Russian cards problem 
should satisfy is that Bob should be informed of Alice’s hand after an announce¬ 
ment. Let us make this precise. First, we introduce an abuse of notation that 
we will use throughout the text. 

If A C 2 n and Y C Cl, define 

A \ Y = {X G A : X n Y = 0}. 

Thus, A \ Y is the set of elements of A avoiding Y. 

Definition 3. Fix integers a, b, c and a deck Cl with |f2| = a + b+c. A strategy © 
on (^) is informative for (a, b, c) if, for every A G (^) and every B G ( n ^) > 
&a\B = {A}. 

Thus after an informative announcement, Bob knows exactly which hand A 
Alice is holding. But an informative strategy may also give Cath information, 
yet we also require for Alice’s strategy to be secure. 

3.2 Probabilistic Security 

Before Alice makes an announcement, Cath knows that Alice can possibly hold 
any hand that doesn’t contain one of Cath’s cards. Hence, there are ( a + b ) 
possible hands for Alice. However, after an announcement, Cath can discard 
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any hand that isn’t found in the announcement. After doing so, it is possible that 
Cath acquires new information about the cards she does not hold. In particular, 
she may know that there is a high probability that Alice holds a given card. 
If Alice and Bob want to communicate securely, it would be desirable to avoid 
giving Cath such information. 

There are three different notions of probabilistic security for strategies: weak, 
perfect, and our notion of e-strong security, which lies between the other two. 
Unconditional security is equivalent to weak security. If we wanted to avoid Cath 
learning any probabilistic information after an announcement, we would need to 
ensure that no card seems more likely after the announcement than it did before. 
For this, the number of hands in the announcement (after Cath eliminates the 
ones which have a card that she holds) that contain a given card must be equal 
for every card that Cath does not hold. In this case, the probability of Alice 
having a set card should stay the same after Alice’s announcement. As a matter 
of fact, we know the value of this probability; we must only count the hands 
that could contain that card given Catli’s hand and divide it by the number of 
remaining hands in the announcement: 


P{x G A\C) 


f6-l\ 
2-1 ) 




rr) 


a 

a + b 


If this number stays constant after Alice’s announcement, we will say that Alice’s 
strategy is perfectly secure. 

Definition 4. A strategy 6 on (^) is perfectly secure for (a, b , c) if for every 
C G (^), every card x G fl \ C, and every announcement A with P(A\C) 0, 
we have that 

P(x£A\C,A) 

P{x G A\C) ~ ' 


This notion is equivalent to 1-perfect security in m and represents Cath’s 
inability to gleam information about the position of individual cards. Compare 
this to weak security, where we only require that Cath is not certain about the 
position of any card she does not hold. 


Definition 5. A strategy 6 on (^) is weakly secure for (a, 6, c) if for every 
C G (^), every card x G tt\C, and every announcement A with P(A\C) ^ 0, 
we have that 


P(x G A\C, A) 
P{x G A\C) 


< 1 . 


In [HI 22 ], the authors present examples of perfectly secure strategies when 
Cath has at most 3 cards. Due to the rigidity needed to ensure this level of 
security, it is not clear whether perfectly secure strategies can be constructed 
when Cath holds more cards. Instead, wc will define an intermediate level of 
security, where the constraint is relaxed so we can have more flexibilty and can 
work in cases where Cath’s hand is larger. In fact, this notion will permit us to 
find secure protocols for any possible hand size that Cath may hold. 
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Definition 6. Let e > 0. A strategy © on (^) is e-strongly secure for (a, b , c) 
if for every C G (^), every card x G it \ C, and every announcement A with 
P(A\C) Y 0, we have that 


P{x G A\C, A) 
P(x G A\C) 


As mentioned above, equitable strategies are useful for simplifying compu¬ 
tations. In particular, the above probabilities may be computed by counting. 
The following result can be found in [HI- 

Leninia 1. Let 6 be an equitable strategy on and (A,B,C) be a deal. 
Suppose that C G (^) and A is an announcement with P(A\C) > 0 and A G A. 
Then, P(A\C,A) = ]^cr 


In other words, the probability that A is Alice’s hand given Cath’s hand 
C and the announcement A (when A is a valid hand given C) is given by the 
quotient of one over the number of hands in the announcement that avoid C. 

Thus the probability of Alice having a set hand A according to Cath is 
Y|.A\C|. However, what we want to calculate is the probability that Alice holds 
a given card x. For this, we introduce a new abuse of notation: for X C 2° and 
y G H, set 

X y = {X G X : y G X}. 

Thus for Z C O, X y \ Z denotes the set of elements of X which contain y but 
avoid Z. The following can also be found in (121. 


Lemma 2. Let & be an equitable strategy on (^) and ( A,B,C) be a deal. 
zen\C, then 


P{z G A\C,A) = 


|A\<?| 

\A \ C\ ■ 


If 


4 Finite geometries 

The geometric strategy is convenient because it allows us to use many familiar 
results from linear algebra. One key difference when working over finite fields 
(instead of, say, R) is that now it becomes relevant to count the number of points 
in a subspace, the number of subspaces touching a point, etc. These quantities 
will be useful more than once in this article. 

First, we recall a general result about the cardinalities of finite fields. Results 
in this section are presented without proof; for a more thorough treatment of 
finite fields and finite geometry, the reader may consult a text such as Gang. 

Theorem 1 (Existence and Uniqueness of Finite Fields). If q is a natural 
number, there exists a finite field with cardinality q if and only if q is of the 
form p n , with p a prime and n a positive integer. This field is unique up to 
isomorphism and is called the Galois Field of order q. We will denote it by 
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Our protocol will be based on affine subspaces of a finite vector space. For 
brevity, we will refer to an affine space of dimension a as an ‘a-plane’, while an 
a-plane passing through the origin (i.e., a linear subspace of dimension a) will 
be referred to as an ‘a-space’. 

Definition 7. Let V be a vector space over a field, F. We say that W C V is 
an a-space if it is a an a-dimensional subspace ofY. 

A subset U C V is an a-plane if it is of the form x + W, where x £ V and 
W is an a-space. Two a-planes X, Y are parallel if there exists y £ V such 
that Y = y + X. 

Thus an a-plane is similar to an a-space, although it does not necessarily 
pass through the origin. If F is finite, then it is not difficult to count the number 
of points on an a-plane. 

Lemma 3. If q is a prime power and V is a vector space over F g , then any 
a-plane in V has exactly q a points. 

Meanwhile, the intersection of two distinct a-planes is either empty or a 
77 -plane for some 77 < a, which has the following consequence. 

Lemma 4. If q is a prime power, V is a vector space over F g and U, W C V 
are distinct a-planes, then 

1. \UnW\< q 01 - 1 and 

2. \UUV\> 2 q a - g a_1 . 

We may also fix a point x in our vector space and instead ask how many 
a-planes meet x. Here the dimension of V will be relevant. We will denote the 
(5-dimensional vector space over F 9 by F^. 

Definition 8. Fix a prime power q. Then, given positive integers a < 5, define 



Lemma 5. Let q be a prime power and 6 > a > 0. Then, 

1. Given x e F^, the total number of a-planes meeting x is equal to [ct\ q ,s- 

2. Given distinct points x,y £ F^, the number of a-planes meeting both x 
and y is given by 



3. The total number of a-planes in F^ is q s a [a]q,s. 
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Proof. For the first claim, we may assume without loss that x = 0. Fix q and let 
k 5 a denote the number of (ordered) sequences v\,... ,v a of linearly independent 
vectors in F^. Observe that, for each a-space W, there are exactly ordered 
bases for W, and thus the total number of a-spaces is precisely fe c/fc“. 

Thus it suffices to find an expression for k 5 a . For iq, we have q s — 1 options, 
since we may choose any vector in save for 0. For V 2 , we have q s — q options, 
since we may choose any vector that does not lie in the line generated by v\. 
More generally, for Vi we have q 5 —q 1 ^ 1 options, since we may choose any vector 
that does not he in the (* — 1) space generated by Vi,..., . Thus the total 

number of options is 

a 

*« = life* - 9*" 1 )’ 

2=1 

and hence the total number of a-spaces is 


kj rnu^-g 1 - 1 ) 
K n t=i(q a - f- 1 ) 




The second claim is proven in a similar fashion. As before, we may assume 
that x = 0 and fix y ^ 0. Then we proceed as above, except that we fix v\ to be 
y. This removes the first factor from both the numerator and the denominator, 
giving us 


[®]g,6 — 


n utf-?- 1 ) 

rnu^-^- 1 ) 


q a - 1 
q s - 1 




Finally, for the third claim, note that if we fix an a-space W, the a-planes 
parallel to W, together with W, form a partition of F^, hence there are i s /q a = 
q 5 ~ a of them. But there are [ a\ qy s different a-spaces, and thus the total number 
of a-planes is g a_a [d] gi j. □ 


5 The Geometric Strategy 

We’ve informally presented the geometric solution to the Russian Cards prob¬ 
lem, and will now formalize it to construct the Geometric Strategy. The protocol 
we will use is essentially presented in [2], The basic idea is to construct a fi¬ 
nite vector space where every point represents a different card and Alice’s hand 
forms an a-plane. Below, we use f[X] to denote the set {f(x): x £ X}. Each 
announcement is parametrized by a suitable map. 

Definition 9. Fix a prime power q, natural numbers 0 < a < 6 and A £ 

We define a suitable map for A to be a function f: H —> F^ such that f[A} is 
an a-plane. 

Given a suitable map f, we define 

A[f] = {X C : f[X] is an a-plane}. 

The geometric strategy is then defined by letting Alice choose uniformly 
from all suitable maps / and announcing A[f]. 
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Definition 10 (The geometric strategy). Let q be a prime power and 0 < a < 8. 
Given a, b and c such that a = q a and a + b + c = q s , we define the geometric 
strategy (with parameters q,a,S), denoted © = <&(q, 6, a), to be the strategy 
such that ©^4 is the set of all announcements of the form A[f], where f: Ll —> 
is suitable for A, and Alice chooses uniformly from &a- 

This strategy generalizes that in [2j where a = 5 — 1, although that article 
also considers the case where Alice holds more than one plane. Let us now show 
that the strategy is equitable. 

Lemma 6. Let q be a prime power, 0 < a < <5 and a = q a , and let © = 
<5(q,5,a). Then, if A, A' g ) , |©a| = |®A'|- 

Proof. Let A, A! g (^). To show that \<&a\ = |©A'|, we will define a bijection 
E: &a —t ©A'- As a first step, we will build a function a that permutes the 
elements of LI. We know that \A \ A'\ = \A' \ A\, so we can find a bijection 
a:A\A' A' \A. 

Using the function s we will define a permutation a : LI —» LI given by 

( s(x) if x g A \ A! 

a(x) = < s _1 (a;) if x g A! \ A 
I x otherwise. 

Since s is invertible, cr is well-defined, and it is easy to check that a is bijective. 
We then define E : ©^ —> ©^ given by E(A) = {a[H]\H g A}. Then, it is easy 
to see that E has an inverse given by E -1 (£>) = { a~ 1 [H] : H g £>}, and hence 
E is a bijection, so that |©^| = |©a'| as claimed. □ 

We have now proven that for every hand that Alice can have there is the same 
number m of possible announcements. This permits us to set the probability of 
a particular announcement to be chosen to 1/m, and thus the geometric strategy 
is equitable. As mentioned above, this will simplify some computations, even 
without explicitly computing to. 

In the remainder of this section we will prove that the geometric strategy 
gives an informative and weakly safe solution to the Russian cards problem, 
provided c satisfies certain bounds. 

Lemma 7. Let q be a prime power, 1 < a < S and a, b, c positive integers such 
that a = q a , a + b + c = q s and c < q a — g“ -1 . Then, the geometric strategy 
with parameters q, 6, a is informative for (a, b, c). 

Proof. Let q, S, a, a, b, c satisfy the hypotheses of the lemma. Let A g (^) and 
B g ( n \ A ) and /: LI —> be such that f[A] is an a-space. Clearly A g <5a, so 
it remains to check that if A' g ( n \ B ) is such that A[f] g ©aa then A = A'. 

If this were not the case, then U = f [A] would be an a-space different from 
U' = f[A']. Since both U and U' are disjoint from f[B\, then so is U U U'. 
By Lemma l4l2l | U U U'\ > 2 q a — q a_1 . But / is a bijection, so it follows that 
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a + c = \A\ + \C\ > 2 q a — g“ _1 , and thus c > q a — contradicting our 

hypothesis. 

We conclude that U = U', so that also A = A' and thus the geometric 
strategy is informative. □ 

Next we must see that, given a card x not held by Cath, there is a nonzero 
probability that Alice holds x, which means that it is impossible that there is 
x £ Ll\C such that all a-spaces passing through x meet C. 

Lemma 8. Let q be a prime power, 0 < a < 6 and a , b , c be such that a = q a 
and a + b + c = q s . Let C £ ( J c 2 ), and f: LI —> be a bijection. If c < ys—y 
and x £ Q\C, there is A £ A[f] such that x € A. 

Proof. Let x £ f l \ C. Recall that [d] f; .a is the number of a-planes meeting 
f(x). If we take z £ C, there are [a\ q j a-planes touching both x and z and, 
since there are c points in C, there are at most c[d ] gj( 5 a-planes touching f(x) 
and meeting f[C]. Thus in order to guarantee that there is at least one a-plane 
touching f{x) but not f[C], it suffices to have c[a\ q j < [d] 9i a. Solving for c and 
using Lemma l5l2l this becomes 

, [Q]g.a = < 1 5 ^ 1 
C< [d],, 5 q«- f 

Thus if c satisfies this constraint, there is an a-space U touching /( x) but not 
meeting f[C\ and A = f~ x \U} is an element of A[f] containing x but disjoint 
from C, as desired. □ 

Likewise, there should be a nonzero probability that any card not held by 
Cath is held by Bob. In other words, if y is not held by Cath, there should be 
an a-plane avoiding y and Cath’s hand. 

Lemma 9. Let q be a prime power, 0 < a < 6 and a , b , c be such that a = q a 
and a + b + c = q 5 . Let C £ (^) and f: LI —>■ be a bijection. If c < q s ~ a and 
y £ Lt\C, there is A £ A[f] such that y ^ A and AllC = 0. 

Proof. Let y £ Ll \ C and z £ C be arbitrary and V be an a-plane touching 
both f(y) and f(z). We know that there are q s ~ a a-planes parallel or equal to 
V. Thus if c < q s ~ a there is at least one a-plane U parallel to V which does 
not contain any pont from C. But by construction, y is not on U either. Thus 
there is an a-plane avoiding both y and U, and we may take A = / -1 [{/]. □ 

Lemma 10. Let q be a prime power, 0 < a < S and a , b , c be such that a = q a 
and a + b + c= q s . Then, the geometric strategy with parameters q, a, 5 is weakly 
secure for (a, b, c) whenever c < q 5 ~ a . 

Proof. It is straightforward to check that q s ~ a < \ , so this is a direct con¬ 
sequence of Lemmas [8] and [9] □ 

Putting together Lemmas 171 and fTOl we obtain the main result of this section. 
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Theorem 2. Let q be a prime power, 0 < a < 6 and a, b , c be such that a = q a 
and a + b + c= q s . Then, the geometric strategy with parameters q, a, S is weakly 
safe and informative for (a, b , c) whenever c < min(g“ — q a ~ l , q s ~ a ). 

We may use Theorem [2] to find many tuples (a, b , c) for which the geometric 
strategy is weakly secure. If Alice holds a line in the plane, then we may take 
c to be almost as large as a: 

Corollary 1. There are infinitely many values of a such that for any c < a — 2 
there is b < a 2 such that the geometric strategy is informative and weakly safe 
for (a,b, c). 

Proof. Take a = 1, S = 2 and q an arbitrary prime power and apply Theorem 

H □ 

On the other hand, if c is much smaller, then we can give Alice a higher¬ 
dimensional plane to ensure that the number of cards is not too large relative 
to Alice and Cath’s hands. 

Corollary 2. Given rational p £ (0,1), there are infinitely many values of a 
such that for any c < a p there is b < a 1+p such that the geometric strategy is 
informative and weakly safe for (a,b,c). 

Proof. Since p is rational, so is 1 + p, so we can find 1 < a < 5 such that 
1 + p = 5 /a. Since p < 1, for large enough q we have that q pa < q a — g“ _1 . 
Thus for such a q we may use Theorem [2] to see that, for a = q a , c < q s ~ a and 
b = q s — a — c, the geometric strategy is informative and weakly safe. Moreover, 
we have that b < q s = qG+p) a = a^ 1+p \ whereas c < q s ~ a = q pa = a p was 
arbitrary, so all desired conditions are met. □ 

Observe that in either case, the geometric strategy gives infinitely many 
solutions for tuples (a, b, c) with c < a and b < ac. 

6 Strong safety of the geometric strategy 

Since the geometric strategy is equitable, we may apply the results in the previ¬ 
ous section to it in order to find parameters for which this strategy is e-strongly 
safe. As we have seen, this strategy is weakly safe if c < q a —q 0-1 and c < q s ~ a . 
Our goal will be to find tuples for which it is e-strongly safe for a given e. 

6.1 Some auxiliary estimates 

We will need to find bounds on the number of hands that Oath considers possi¬ 
ble. We begin by counting the total number of hands in an announcement. The 
following is a direct consequence of Lemma [5] 

Lemma 11 . The number of a-sets in an announcement A of the geometric 
strategy with parameters q,S,a is q s ~ a [d] gi 5 . 
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Now let us see how many hands Cath can discard from this announcement. 
Recall that A \ C denotes the set of lines avoiding C and A X \C denotes the set 
of lines avoiding C that also pass through x. We may compute the probability 
that Alice holds x from Cath’s perspective as 


P{x G A\C, A) 


IA \ c\ 

\A \ C\ • 


What we are interested in is bounding the quotient of Cath’s perceived proba- 
bilites before and after the announcement, that is, 


P(x€ A\C,A) = A*\c\/\ A \ C \ 

P{X G A\C) a /a+b ' ' ’ 

As we will see, by modifying the parameters, this quotient can become arbitrarily 
close to 1. 

In order to find bounds for CD, it suffices to bound the numerator, since the 
denominator is constant. Thus we need to estimate \A X \ C\ and |A \ G\. Let 
us begin with the latter. 


Lemma 12. If A is an announcement of the geometric strategy with parameters 
a,S,q and C G (^) is non-empty, then 

[a] q ,s(q S ~ a - c) < |-4. \ C\ < [a) q ,s(q 5 ~ a - 1). (2) 


Both equalities hold whenever c = 1. 

Proof By Lemma [III |A| = q s ~ a [d] 9 , 5 - Thus we may estimate the number of 
a-planes that meet C and subtract to obtain our bounds. 

Suppose that A = A[f\. To bound |A\C| from below, observe that there are 
[d ] 9j 5 a-planes passing through each point in f[C] and there are c such points, 
so that the number of hands in A meeting C , which is equal to the number of 
a-planes touching f[C], is at most c[a\ qA . It follows that 

[a) q , 5 (q s - a -c)<\A\C\. 

Observe that when c > 1 we are subtracting one a-plane at least twice so the 
inequality is strict, but when c = 1 then equality holds. 

Now let us show the right-hand inequality. Since C/0, we can pick z G C 
and observe that there are [d] g ^ a-planes meeting f(z ), and thus at least [d ] 9j 5 
meeting f[C]. It follows that 

\A\C\ < [a} q , S q S ~ a ~ [a] q ,8 = [a) qA (q s ~ a - 1), 

and if C = {z} this computation is exact. □ 


Lemma 13. If A is an announcement of the geometric strategy with parameters 
a,8,q and C G (^) is non-empty, then 

— A x \ C\ A [d]q- i( 5 [d]g ; 5- (3) 

Equality holds when c = 1. 
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Proof. Once again suppose that A = A[f}. First let us bound | A x \ C\ from 
below. To give our estimate, we will take the number of a-planes passing through 
/( x) and subtract the number of a-planes passing through f(x) and f{y) for 
each y £ C, without taking into account that many a-planes will be subtracted 
twice. Evidently this bound will not be tight, but it will be sufficient to establish 
our main results. 

Recall that [a ] q ,5 counts all of the a-planes passing through a given point. 
But, there are [d ] 9j 5 a-planes passing through f(x) and f(y) for each y £ C, 
and thus there are at most c[a] q j planes meeting both f{x ) and f[C], hence 
also hands in A meeting x and C. It follows that 

[b?]g,(5 — | Ax \ C |. 

Now let us bound \A X \ C | from above. This time we use the fact that there 
is at least one yo £ C, and we can discard all of those a-planes that touch f(yo) 
as well as f(x), of which there are [S]^. It follows that 

I A x \ C | ft [a]g 5 ,5 

and the result follows. Once again this bound is exact when c = 1. □ 


6.2 Bounding probabilities 

The counting lemmas we have given above may be used to bound the probabil¬ 
ities we are interested in. First, we give a more exact bound, and later we will 
give a simplified version. 

Lemma 14. If A is an announcement of the geometric strategy with parameters 
q,a,S and C £ ( n ) is non-empty, 

q 2S _ cq 6+a ^ q s + c 2( g q _ j) + c P(z g A\C, A) 
q 2 S _ q s _ q s+a + q a - P( X £ A\C) 

and 

P(x £ A\C, A) < q 2S - cq 5 - q s+a + cq a 
P{x £ A\C) ~ q 2S - cq s+a - q s + cq a ' 

Proof. For the lower bound, we put the lower bound of Lemma [13] together with 
the upper bound of Lemma [T3] to obtain 


[d]g ; 5 [d]g^C ^ | A x \ C | 
[d\ q , s (q s - a -l)~~\A\C\ 


= P{x £ A\C,A). 


Using Lemma 15121 and simplifying we obtain 


q s — cq a + c — 1 

q 26—a _ q S-a _ q 5 + 4 


< P(x £ A\C, A). 
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Figure 3: Some choices of parameters for the geometric strategy along with their 
respective lower and upper bounds given by Lemma 1141 These were found by 
fixing c £ {2, 3,4}, a < 3 and 5 = a + 1 and finding the least q for which the 
strategy is 0.05-strongly safe. 


Thus, 

qld-a _qd-a _qd + 1 ^ P(x £ A\C, A) 

=f= - P(xeA\C) ; 

using the equalities a = q a and a + b + c = q s and simplifying once again we 
obtain 

q 2S _ cq 5+a _ q 8 + c 2( g « _ j) + c p( x g A\C,A) 
q 2S _ q 8 _ q 8+ a + q a - P(x£A\C) 

Now we turn to bounding the quotient of probabilities from above. As before, 
we focus on the numerator, since the denominator is fixed, and use Lemma m 
bound | A x \ C | from above and Lemma fl2l to bound | A \ C\ from below. 

Thus we obtain the following upper bound: 

|Ax \ C | 

|A\C| ” [a] q ^{q 5 ~ a - c)‘ 

Once again we may use Lemma 15121 and some algebra to obtain 

P{x £ A\C, A) < q 25 - cq 5 - q s+a + cq a 
P(x £ A\C) ~ q 2S — cq s+a — q 5 + cq a 

Example 1. Let q = 2 14 , a = 1 and 5 = 3. This gives rise to the triple 

a = 16,384 

b = 4,398,046,494,716 
c = 4. 

Although the number of cards is rather large, this triple is remarkable in that 
it may be considered floating-point perfectly secure; indeed, by Lemma [7|] the 
geometric strategy is 1.118 x 10 ~ 8 -strongly safe for this choice of parameters. 
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In fact, when q is large, some simpler bounds will suffice for our purposes. 

Corollary 3. If A is an announcement of the geometric strategy with parame¬ 
ters a, S and C G (^) is non-empty, then 


1 - 


cq 


and 


q s - 1 

P{x G A\C, A) 


< 


P{x G A\C) 


< 1 + 


P(x G A\C, A) 

P(x G A\C) 

c(q S + 1) + q S ~ a 


q2S-a _ C gS _ qS-c 


( 6 ) 


(7) 


Proof. Observe that, since 5 > 2, it follows that — q s+a + q a < 0; thus we can 
remove this term from the denominator in 0, as well as some positive terms 
from the numerator to obtain 


q 2S _ cq 5+a _ qS p( x e A ) 


q28 _ q s 


P{x G A\C) 


which gives us our lower bound (0 by simplifying. 

We may also obtain a simpler upper bound by removing negative terms from 
the numerator and positive terms from the denominator, giving us 


P{x G A\C,A) 
P(x G A\C) 


q 25 + cq a 


q' 25 — cq s+a — q s ’ 


which factoring q a and performing polynomial division becomes our simplified 
upper bound 0. □ 


6.3 Convergence 

Our simplified bounds from Corollary [3] will be enough to yield many tuples 
for which the geometric strategy is £-strongly safe for arbitrarily small e. It is 
based on the following. 

Theorem 3. Let £ > 0, 1 < a < <5 and c: N —> N be such that c(q) = o(q 5 ~ a ). 
Then, if q is a large enough prime power, the geometric strategy with parameters 
q , a , 6 is e-strongly safe for any c < c{q). 


Proof If c(q) = o(q s ~ a ) then 1 - ^ and 1 + 
to 1 as q —» oo. It follows from Corollary [3] that if q is large and c < c(q), 


nrjr both converge 


P{x G A\C, A) 


- 1 


< E, 


P{x G A\C) 

which means that the geometric strategy is £-strongly safe. 


□ 


However, convergence may be quicker or slower depending on how we choose 
c. For example, if we fix £ > 0 and take c(q) = , then this quotient will 

tend to one, but if £ is very small we may need a very large number of cards for 
it to be less than some given e. More generally, we have the following: 
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Theorem 4. Fix 1 < a < 5, £ £ (0, <5 — a) and c: N —>■ N with c(q) < q s ~ a ~^. 
Then, for q a prime power, any announcement A of the geometric strategy any 
card x and any set of C cards with at most c(q) elements, 


P(x G A\C,A) 
P{x e A\C) 


1 + o(V 9 s ). 


Proof. If we take c = c(q) < q 5 “ we have that 


q 


cq 




< 


s - 1 ~ q 5 -1 


o(m 


whereas 


c(q s + 1) + q 5 ~ a ^ q 2S ~ a -t + q s - a -t + q s ~ a 

q25—ot _ cq& _ q^~ a q28—ot _ q25—ot—£ _ q5—ot 


o(V^). 


The theorem then follows from Corollary [3] 


□ 


Here we see a trade-off between keeping Cath’s hand relatively large and 
obtaining a good rate of convergence for our bounds. Observe, however, that 
the larger c is, the less tight our bounds are, so despite our bounds converging 
rather slowly there may be smaller examples with a large degree of security. 


7 Choosing good parameters 

In this section we will focus on strategies for finding specific choices of parame¬ 
ters for which the geometric protocol is e-safe. In particular, we will fix e = 0.05, 
and use our bounds to find several explicit tuples for which the geometric strat¬ 
egy is e-safe. It is interesting to compare this to m, where many choices of 
parameters for which the protocol is perfectly safe are exhibited. All of the tu¬ 
ples presented there have c < 3, and the authors discuss the difficulty of finding 
perfectly safe strategies for larger c. As we shall see this becomes substantially 
simpler if we weaken our requirements to (e.g.) 0.05-strong safety. Thus we may 
argue that passing to a weaker notion of security allows us to make the Russian 
cards problem substantially easier to solve without compromising security in a 
practically meaningful way. 

7.1 Cath has one card 

The notion of perfect security for the Russian cards problem was introduced in 
m, where several examples with c = 1 are provided. Here we will show that, 
in this setting, the bounds we have found may also be used to establish perfect 
security in the case of the geometric strategy. 

Corollary 4. Given 1 < a < 5 and a prime power q, the geometric strategy is 
perfectly safe for (a, b , 1) with a = q a and b = q s — a — 1. 
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Proof. We will use our original bounds from Lemma ITT! Setting c = 1 in © we 
see that 

P(x £ A\C, A) < q 2S - q s - q s+a + q a _ 

P(x £ A\C) ~ q 2S — q s+a — q 5 + q a 
Similarly, we substitute c = 1 in © to obtain 

s _ q 25 - q s+a -q 5 + q a -1 + 1 < P(x £ A\C , A) 
q 2S _ gS _ qS+a _|_ — p( x g A\C) 

Thus we have seen that P< p^a\c)^ = lh a l ^ s ’ ^(a; G A|C, .4.) = P(a; S A|C). 

□ 

Hence our bounds give an alternative proof that the geometric strategy is 
perfectly secure when c = 1. Now let us turn our attention to larger c. 

7.2 Making Cath’s hand large 

Suppose that we wish to obtain good tuples for which c is as large as possible 
relative to Alice’s hand. Cath’s hand is bounded by two expressions on a , one 
increasing on a (c < q a — q a ~ l ) and one decreasing (c = o(q s ~ a )). Thus, the 
maximum value that c may take is when the two bounds coincide, which occurs 
approximately when 8 = 2a or <5 = 2a + 1 . 

The latter case is interesting, since we already have that q a — q a ~ 1 < q & ~ a ~ x . 
Thus in cases that Alice holds relatively few cards, less than the square root of 
the deck, our informativity bound will already give us e-strong safety for large 
values of q. To be precise, we have the following: 

Corollary 5. Let e,/3 > 0 and 7 £ (0,1). Then, there are infinitely many 
values of a such that for any c < 7 a there is b < a 2+/3 so that the geometric 
strategy is informative and e-strongly safe for (a, b, c). 

Proof. Let e, /3 > 0 and 7 £ (0,1). Pick a large enough so that l /a < (3 and Q 
large enough so that 1 /q < O--A/ 2 . Set 8 = 2a + 1 and c(q) = q a + q Q_1 — 1. 
Then, since 8 — a = a + 1 we have that c{q) = o(q s ~ a ), from which it follows 
from Theorem [3] that for large q , the geometric strategy is informative and e- 
strongly safe for a = q a , c < c.{q) and b = q s — a — c. In particular we may also 
take q > Q, so that 

c(q) = q a ~ <?“ _1 - 1 = (1 - V? - V g a )a > 7 a. 

Meanwhile, b < q s = (q a )~^~ < a 2+|S , so all desired conditions are met. □ 

Compare the above result to Corollary |T] As before we can have c = O(a), 
but this time instead of having b < ac we must take b = 0(ac 1+/3 ). Thus the 
price of obtaining £-strong security is to make Bob’s hand a bit larger than we 
would need for weak security. In Figure 01 we fix values of 7 and /3 and use 
the strategy of Corollary [5] and its proof to find tuples for which the protocol is 
0.5-strongly secure. 
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Figure 4: Tuples for which the geometric strategy is 0.5-strongly secure with q 
a prime power, a = q a , c > 7 a, and b = q 2a+1 — a — c. 

7.3 Making Bob’s hand small 

We may also give a e-strongly secure analogue of Corollary [2] Suppose that we 
instead want to have a small number of cards in Bob’s hand relative to Alice’s. 
In our above construction Bob’s hand grew relatively quickly, so we want a 
different strategy for selecting parameters. The trade-off will be that Cath’s 
hand may be substantially smaller than Alice’s. In general if we want Bob to 
have less than a 1+ @ cards, then Cath must have less than a 7 for some 7 < /?. 

Corollary 6. Let e > 0, 7 € (0, 1) and f3 > 7 be such that f} £ Q. Then, there 
are infinitely many values of a such that for any c < a 1 there is b < a 1+ @ such 
that the geometric strategy is informative and e-strongly safe for ( a,b,c ). 

Proof. Similar to the proof of Corollary[2] but taking c < q ia and using Theorem 

E3 □ 

Once again, we may obtain e-strong security for infinitely many tuples 
(a,b,c) where c < a and b = 0(ac 1+ &). So the takeaway in either case is 
that, making Bob’s hand only a bit bigger compared to the rest of the deck and 
choosing an appropriately large deck, we may obtain e-strong security instead 
of merely weak security. In Figure [5] we use this idea to find additional tuples 
for which the geometric protocol is 0.5-safe. 

8 Concluding remarks 

While the Russian cards provides a setting in which we may attain uncondition¬ 
ally safe communication, many known solutions to the Russian cards problem 
are only weakly safe, meaning that they may provide the eavesdropper with 
probabilistic information. Although perfectly secure solutions are known, it is 
somewhat difficult to find tuples for which this level of security may be attained. 
In this paper we have shown, however, that the amount of probabilistic infor¬ 
mation obtained by the eavesdropper may be controlled, to the extent that in 
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Figure 5: Tuples for which the geometric strategy is 0.05-strongly secure with 
q a prime power, 5 > a > 0, 7 < s /a — 1, a = q a , c = |_n 7 J, and b = q s — a — c. 


some cases we can obtain a degree of safety indistinguishable from perfect safety 
for all practical purposes. Weakening the notion of perfect security has led to 
an infinite number of new tuples for which we may still obtain a high degree of 
security, and indeed the bounds we have given may be used to analyze the level 
of security in any instance of the geometric strategy. Moreover, our techniques 
had the added bonus of replicating some results of m- 

There are further directions that may be explored. Although our bounds 
are tight when c = 1, the larger c is, the less exact they are, which may keep us 
from identifying many tuples for which we have a high degree of security. These 
bounds may be improved with a deeper (and, possibly, messier) combinatorial 
analysis which takes into account collinear points using the inclusion-exclusion 
principle. In fact, tailor-made bounds can be used for specific values of c that 
may be of interest. 

Finally, this analysis could be generalized further to include other combi¬ 
natorial constructions, for example considering a wider class of designs. Such 
efforts could very well lead to more flexible methods of finding tuples for which 
there are strategies with very high levels of security. 
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